Vault Lock enforces write-once-read-many (WORM) protection on your AWS Backup vault, so backups can’t be deleted or shortened before their retention period — even by administrators. It’s ransomware and compliance insurance for backups.

The tell

When a scenario requires that backups themselves cannot be deleted or altered for a retention period (protection against ransomware or malicious insiders), that’s Backup Vault Lock in compliance mode. It’s the backup-layer equivalent of S3 Object Lock.

Test yourself

Practice question

A company must guarantee that its backups cannot be deleted or have their retention shortened by anyone, including admins, for compliance. What enforces this?

  1. A restrictive IAM policy
  2. AWS Backup Vault Lock (compliance mode)
  3. S3 Versioning
  4. More frequent backups
👉 Click to reveal the answer & explanation

Correct answer: B. Vault Lock in compliance mode enforces immutable WORM protection on backups so no one can delete or shorten retention. An IAM policy (A) can be changed; S3 Versioning (C) protects objects, not backup vaults; more frequent backups (D) don’t prevent deletion.

Related topics

AWS Backup · S3 Object Lock · Disaster Recovery Strategies

CloudExamPro Premium

Ready to pass the AWS Solutions Architect Associate (SAA-C03)?

Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.

  • ✓  6 full-length practice exams
  • ✓  A detailed explanation for every single question
  • ✓  Realistic, scenario-based questions — not memory dumps
  • ✓  Lifetime access, kept current for 2026

Get the SAA-C03 Practice Exams →or try 25 free questions first

Limited-time offer · ends in --Days:--Hrs:--Min:--Sec
Get Instant Access